|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Check Point FW-1
From: Roman Shterenzon (roman
xpert.com)Date: Sun Oct 08 2000 - 18:03:08 CDT
- Next message: Crist J . Clark: "Re: Check Point FW-1"
- Previous message: Tony Finch: "Re: A new problem in apache ?"
- In reply to: Crist J . Clark: "Re: Check Point FW-1"
- Next in thread: Crist J . Clark: "Re: Check Point FW-1"
- Reply: Roman Shterenzon: "Re: Check Point FW-1"
- Reply: Crist J . Clark: "Re: Check Point FW-1"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Sun, 8 Oct 2000, Crist J . Clark wrote:
> On Sat, Oct 07, 2000 at 01:33:04PM -0400, Brian Reichert wrote:
> > On Fri, Oct 06, 2000 at 10:57:37PM -0700, Craig Cowen wrote:
> > > The big cheeses at work want to use check point instead of ipf or any
> > > other open source solution.
> > > Can anybody help me with vunerabilities to this so that I can change
> > > thier minds?
> >
> > I found that Checkpoint 4.0 (this may have changed) doesn't do NAT
> > right; it uses NAT across _all_ interfaces, instead of letting you
> > pick one.
>
> Right, it determines whether to do NAT by source address, destination
> address, and destination port. Actually, it is not possible to do
> _anything_ per interface from the GUI. Wouldn't it be nice (and
> wouldn't you expect a firewall to be able) to block anything not
> destined for a small block of registered IPs at the external
> interface? Well, you can't put a rule to do that in the GUI.
That's rule 0 - it does antispoofing stuff.
It's really simple. From the GUI.
Now, does it have anything to do with FreeBSD-security?
--Roman Shterenzon, UNIX System Administrator and Consultant
[ Xpert UNIX Systems Ltd., Herzlia, Israel. Tel: +972-9-9522361 ]
To Unsubscribe: send mail to majordomo
FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message
- Next message: Crist J . Clark: "Re: Check Point FW-1"
- Previous message: Tony Finch: "Re: A new problem in apache ?"
- In reply to: Crist J . Clark: "Re: Check Point FW-1"
- Next in thread: Crist J . Clark: "Re: Check Point FW-1"
- Reply: Roman Shterenzon: "Re: Check Point FW-1"
- Reply: Crist J . Clark: "Re: Check Point FW-1"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]